- Component Type: TYPO3 CMS
- Vulnerable subcomponent: User Authentication (ext:core)
- Release Date: May 7, 2019
- Vulnerability Type: Information Disclosure
- Affected Versions: 9.0.0-9.5.5
- Severity: Medium
- Suggested CVSS v3.0: AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
- CVE: not assigned yet
Problem Description
It has been discovered that login failures have been logged on the default stream with log level "warning" including plain-text user credentials.
Solution
Update to TYPO3 version 9.5.6 that fixes the problem described. The according log level has been changed to "debug" which needs to be enabled explicitly.
Credits
Thanks to Helmut Hummel who reported and fixed this issue.
General Advice
Follow the recommendations that are given in the TYPO3 Security Guide. Please subscribe to the typo3-announce mailing list.
General Note
All security related code changes are tagged so that you can easily look them up in our review system.